Static | ZeroBOX

PE Compile Time

2060-12-09 15:27:19

PDB Path

D:\.000.Private\000.NET\VvMain\q0\4.0\VvFile\VvFile\obj\Release\v.pdb

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00003cb8 0x00003e00 5.6483655262
.rsrc 0x00006000 0x00000584 0x00000600 3.99728443413
.reloc 0x00008000 0x0000000c 0x00000200 0.0815394123432

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x00006090 0x000002f4 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x00006394 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
v4.0.30319
#Strings
<Module>
GW_CHILD
RESTORE
WM_CLOSE
WM_MOUSEMOVE
MINIMIZE
MAXIMIZE
BM_CLICK
WM_LBUTTONDBLCLK
WM_RBUTTONDBLCLK
WM_LBUTTONDOWN
WM_RBUTTONDOWN
WM_SYSKEYDOWN
WM_KEYDOWN
System.IO
WM_LBUTTONUP
WM_RBUTTONUP
GW_ENABLEDPOPUP
GW_OWNER
VK_ENTER
WM_QUIT
GW_HWNDLAST
GW_HWNDFIRST
GW_HWNDNEXT
GW_HWNDPREV
WM_NCDESTROY
WM_DESTORY
value__
mscorlib
set_Verb
Thread
Form1_Load
add_Load
FrameChanged
get_InvokeRequired
Synchronized
GetWindow_Cmd
set_IsBackground
method
RunService
defaultInstance
set_AutoScaleMode
get_Message
SendMessage
PostMessage
SendNotifyMessage
EndInvoke
BeginInvoke
IDisposable
set_Visible
RuntimeTypeHandle
GetTypeFromHandle
windowHandle
DownloadFile
VvFile
IsInRole
WindowsBuiltInRole
ThisConsole
DockStyle
set_BorderStyle
set_FormBorderStyle
set_Name
set_FileName
get_MachineName
IpClassName
GetHostName
IpWindowName
DrawFrame
DateTime
WriteLine
set_Multiline
get_Culture
set_Culture
resourceCulture
ApplicationSettingsBase
TextBoxBase
DeferErase
Dispose
MulticastDelegate
EditorBrowsableState
set_WindowState
FormWindowState
DoNotActivate
Delete
get_White
STAThreadAttribute
CompilerGeneratedAttribute
GuidAttribute
GeneratedCodeAttribute
DebuggerNonUserCodeAttribute
DebuggableAttribute
EditorBrowsableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
TargetFrameworkAttribute
AssemblyFileVersionAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
FlagsAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
set_UseShellExecute
IgnoreMove
get_Size
set_Size
set_ClientSize
IgnoreResize
System.Threading
System.Runtime.Versioning
UploadString
ToString
disposing
System.Drawing
get_ExecutablePath
GetFolderPath
SetTextCallBack
AsyncCallback
callback
get_Black
set_Dock
System.Security.Principal
WindowsPrincipal
System.ComponentModel
kernel32.dll
user32.dll
ContainerControl
IParam
MakeLParam
lParam
wParam
Program
get_Item
System
resourceMan
FrmMain
set_ShowIcon
Application
set_Location
System.Configuration
System.Globalization
System.Reflection
ControlCollection
ManagementObjectCollection
set_StartPosition
FormStartPosition
AsynchronousWindowPosition
DoNotReposition
Exception
CultureInfo
ProcessStartInfo
DirectoryInfo
getLocalIp
set_WordWrap
set_TabStop
set_ShowInTaskbar
ToChar
SpecialFolder
sender
IgnoreZOrder
DoNotChangeOwnerZOrder
get_ResourceManager
ManagementObjectSearcher
EventHandler
System.CodeDom.Compiler
IContainer
logonUser
windowHandleInsertAfter
set_ForeColor
set_BackColor
ManagementObjectEnumerator
GetEnumerator
IsAdministrator
.cctor
IntPtr
System.Diagnostics
System.Runtime.InteropServices
System.Runtime.CompilerServices
System.Resources
VvFile.FrmMain.resources
VvFile.Properties.Resources.resources
DebuggingModes
VvFile.Properties
EnableVisualStyles
GetManifestResourceNames
SetWindowPosFlags
Settings
EventArgs
get_Controls
System.Windows.Forms
set_AutoScaleDimensions
SetWindowPos
set_ScrollBars
Process
IPAddress
System.Net.Sockets
DoNotCopyBits
components
Exists
Concat
ManagementBaseObject
ManagementObject
object
System.Net
ScrollToCaret
height
op_Explicit
get_Default
SetCompatibleTextRenderingDefault
IAsyncResult
DialogResult
result
WebClient
System.Management
Environment
InitializeComponent
get_Current
GetCurrent
DoNotSendChangingEvent
ThreadStart
Convert
get_AddressList
SuspendLayout
ResumeLayout
PerformLayout
MoveNext
set_Text
AppendText
SetText
DoNotRedraw
get_Now
FindWindow
HideWindow
GetConsoleWindow
GetWindow
ShowWindow
nCmdShow
FindWindowEx
set_TabIndex
MessageBox
TextBox
get_Assembly
GetExecutingAssembly
get_AddressFamily
CreateDirectory
set_WorkingDirectory
get_CurrentDirectory
txthistory
IPHostEntry
GetHostEntry
op_Equality
WindowsIdentity
IsNullOrEmpty
WrapNonExceptionThrows
VvFile
Copyright
2021
$94a8e7f9-2b18-4743-a887-e16fc0c405f4
1.0.0.0
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4A
3System.Resources.Tools.StronglyTypedResourceBuilder
15.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
15.9.0.0
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
D:\.000.Private\000.NET\VvMain\q0\4.0\VvFile\VvFile\obj\Release\v.pdb
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
WinPcap 4.1.3 Setup
Button
&Next >
&Install
WinPcap 4.1.3 Setup
I &Agree
&Finish
yyyy.MM.dd HH:mm:ss
C:\Program Files (x86)\WinPcap
_64.exe
_64.zip
_x64.exe
_64.dll
_32.exe
_32.zip
_x86.exe
_32.dll
C:\Program Files\WinPcap
C:\Windows\SysWOW64\
C:\Windows\
C:\Users\
\AppData\Roaming\Microsoft\Windows\system32\
\Microsoft\Windows\
http://113.212.88.60/Vv/1/
sc.exe
\sc.exe
RuntimeBroker
RuntimeBroker.exe
stop svchost
<FAIL><STOP SERVICE> MachineName :
, Ip :
, User :
, Bit1 :
http://113.212.88.60:88/log
RuntimeBrokerBin
WinPcap_4_1_3.exe
vcredist_2010
vcredist_2013
PcapDotNet.Base
PcapDotNet.Base.dll
PcapDotNet.Core
PcapDotNet.Core.dll
PcapDotNet.Core.Extensions
PcapDotNet.Core.Extensions.dll
PcapDotNet.Packets
PcapDotNet.Packets.dll
PcapDotNet.Analysis
PcapDotNet.Analysis.dll
/q /norestart
create svchost binPath=
RuntimeBroker.exe start= auto DisplayName= svchost
description svchost "
(VPN)
start svchost
<SUCCESS> MachineName :
, Bit :
<FAIL> MachineName :
root\CIMV2
SELECT username FROM Win32_ComputerSystem
username
txthistory
FrmMain
VvFile.Properties.Resources
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
CompanyName
FileDescription
VvFile
FileVersion
1.0.0.0
InternalName
LegalCopyright
Copyright
2021
LegalTrademarks
OriginalFilename
ProductName
VvFile
ProductVersion
1.0.0.0
Assembly Version
1.0.0.0
Antivirus Signature
Bkav Clean
Lionic Trojan.MSIL.Agent.b!c
Elastic Clean
MicroWorld-eScan Gen:Variant.MSILHeracles.25837
FireEye Generic.mg.b118cd4261d84677
CAT-QuickHeal Trojan.YakbeexMSIL.ZZ4
ALYac Gen:Variant.MSILHeracles.25837
Cylance Unsafe
Zillya Clean
Sangfor Trojan.MSIL.Agent.gen
K7AntiVirus Clean
BitDefender Gen:Variant.MSILHeracles.25837
K7GW Clean
CrowdStrike win/malicious_confidence_60% (W)
Baidu Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
ESET-NOD32 Clean
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky HEUR:Trojan-Dropper.MSIL.Agent.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
Ad-Aware Gen:Variant.MSILHeracles.25837
Sophos Mal/Generic-S
Comodo Clean
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro TROJ_GEN.R002C0PK121
McAfee-GW-Edition GenericRXIT-RW!B118CD4261D8
CMC Clean
Emsisoft Gen:Variant.MSILHeracles.25837 (B)
SentinelOne Static AI - Malicious PE
GData Gen:Variant.MSILHeracles.25837
Jiangmin Clean
Webroot Clean
Avira TR/ATRAPS.Gen
MAX malware (ai score=89)
Antiy-AVL Clean
Kingsoft Win32.Troj.Undef.(kcloud)
Gridinsoft Clean
Arcabit Trojan.MSILHeracles.D64ED
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Sabsik.FL.B!ml
Cynet Malicious (score: 99)
AhnLab-V3 Clean
Acronis Clean
McAfee GenericRXIT-RW!B118CD4261D8
TACHYON Clean
VBA32 Clean
Malwarebytes Trojan.Dropper.SVC
Panda Trj/GdSda.A
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Msil.Trojan-dropper.Agent.Pbeu
Yandex Clean
Ikarus Trojan.Agent
eGambit Clean
Fortinet PossibleThreat
BitDefenderTheta Gen:NN.ZemsilF.34236.bm0@aiXtFwp
AVG Win32:MalwareX-gen [Trj]
Cybereason malicious.a9868a
Avast Win32:MalwareX-gen [Trj]
MaxSecure Trojan.Malware.300983.susgen
No IRMA results available.